Mozilla is an open-source Web browser, designed for standards compliance, performance and portability.
Mozilla is a cousin to Netscape Communicator that is being developed by the Free Software Community with the cooperation and support of Netscape. What’s New in This Release:
路 Drag and drop loading of privileged XUL
路 GIF heap overflow parsing Netscape extension 2
路 Internationalized Domain Name (IDN) homograph spoofing
路 Unsafe /tmp/plugtmp directory exploitable to erase user’s files
路 Plugins can be used to load privileged content
路 Cross-site scripting by dropping javascript: link on tab
路 Image drag and drop executable spoofing
路 HTTP auth prompt tab spoofing
路 Download dialog source spoofing
路 Overwrite arbitrary files downloading .lnk twice
路 XSLT can include stylesheets from arbitrary hosts
路 Memory overwrite in string library
路 Install source spoofing with user:pass@host
路 Spoofing download and security dialogs with overlapping windows
路 Heap overflow possible in UTF8 to Unicode conversion
路 SSL “secure site” indicator spoofing
路 Window Injection Spoofing
Download